Reading the results

Attack surface

Everything reachable from outside, in one table, with the unknowns marked as unknown.

What it collects

Hosts, subdomains, certificates, the technologies fingerprinted on each, whether an origin sits behind a CDN or WAF, and the endpoints discovered along the way. It is the outside view of the estate, assembled from every scan rather than from a single one.

The attack surface table listing hosts with their technologies, certificates and origin protection.

Reading the blanks

A column can be blank for two different reasons, and the table distinguishes them. Nothing found is not the same as never checked, and the second is rendered differently precisely so it cannot be mistaken for the first.

What this does not do

No port scanning is performed. Nothing in the platform does port discovery, so open ports are absent rather than reported as closed.